Data processing addendum
Processor terms for business customers: roles, processing purposes and retention, current subprocessors and processor categories, security measures, and change notices.
On this page
This page is the processing addendum for customers who need one on file. It states who processes what when you use the API or the console, and it binds us to the same facts the privacy page states in plain language. If your compliance process needs a countersigned copy, mail support@tiyuvta.ai and we will execute this text as a PDF.
Roles
For the content of your requests (prompts, file inputs, completions) you are the controller and tiyuvta (sole proprietorship, Israel) is the processor. By default we process that content to answer the request. Additional processing applies when promotional credit funds the request or when you enable the training setting, as described below.Paddle.com Market Ltd is the merchant of record for payments and acts as an independent controller for the payment data it collects; we do not receive your card number. Paddle also appears on the sub-processors page for completeness; for payment data it is a controller, not our processor.
What is processed, and for how long
- Prompts and completions: purchased credit, training off
- Not written to the durable capture corpus or used for training, fine-tuning, distillation or evaluation. Prompt prefixes may remain in engine memory after a response until evicted or the process restarts. The gateway namespaces prefix reuse by account and cache_salt, not by individual API key.
- Prompts and completions: promotional credit, or paid with the training switch on
- May be retained and used to improve our models under the privacy terms. The setting is recorded per captured request, so which rule applied is auditable. Captured training data is subject to a 24-month deletion policy; account closure starts a 30-day purge deadline, whichever comes first. Purging is performed by our deletion process, with overdue closure alerts and a validated deletion receipt; turning consent off stops new capture, not the retention clock for existing data.
- Billing metadata
- Billing records contain request identifiers, account or tenant identifiers, API key prefixes where available (not full keys), model, route, timestamps, outcome, token counts and cost; they do not contain prompt or completion bodies. Kept up to 12 months.
- Operational logs
- Status codes, latency, error classes, calling IP; no request content. Kept up to 30 days.
- Account data
- Email, verified login-provider identity, key prefixes, credit ledger, and sign-up abuse case decisions. Kept while the account exists. Short-lived network and local-part correlation evidence is removed after 30 days.
Subprocessors
Current named subprocessors and the compute-provider category used to run each model are listed below. Mail support@tiyuvta.ai for the current compute provider’s legal entity before sending production data that requires a named-vendor review.
- Cloudflare, Inc. (US, global edge): site and API delivery, DDoS and TLS termination, the console application, D1 databases, R2 encrypted capture archives, Analytics Engine and outbound email. Cloudflare operates global infrastructure; this policy does not promise EU-only storage.
- Paddle.com Market Ltd (UK/EU): payments, tax, invoicing, saved payment methods, as merchant of record.
- GPU compute providers: the datacenters the models run in. Trial requests are processed in Europe (Finland); the subprocessors page names the compute provider. Request content and prefix-cache state follow the capture and retention rules above.
Security measures
- TLS on every public surface; no plaintext listener exists.
- API access by bearer key only; keys are revocable per key and scoped to trial requests and model discovery; a customer key cannot reach admin, billing or key management.
- Administrative surfaces are on a separate origin behind service-token access control, never on the API host.
- Per-tenant cache isolation: one account's cached prefixes are never served to another account, in either direction.
- Billing records are content-free by construction: the metering pipeline carries token counts, never text.
Data subject requests and deletion
Mail support@tiyuvta.ai. Access, correction and deletion work as the privacy page states; deletion removes the account, keys and email while the content-free billing records complete their statutory retention.
International transfers
Trial requests run in Europe (Finland). Cloudflare operates global infrastructure; this policy does not promise EU-only storage. Payments run underPaddle.com Market Ltd’s own compliance regime as merchant of record.
Changes to this list
Adding or replacing a subprocessor is announced by email before it takes effect, like every change that widens what happens to your data. The date at the top moves with every change.